What SiteLens Professional does—and what it does not do.
This page describes the current subscription product so customers can distinguish implemented controls from unsupported assumptions or contractual guarantees.
Named-presenter access
Presenter access is tied to a signed-in email and an active subscription record. SiteLens stores a keyed, one-way identifier for that email in billing records rather than the raw address. Access is not expanded when payment, webhook, subscription, refund, dispute, or reconciliation state is incomplete or inconsistent.
Payment separation
Stripe provides checkout and the billing portal. SiteLens validates the configured plan, recurring interval, amount, mode, and quantity before opening checkout, and uses signed billing events and reconciliation to update access. Plan and document content, filenames, participant links, and session activity are not sent to Stripe.
Presenter and participant controls
- A signed-in subscriber receives a separate presenter control capability for each session.
- A participant link cannot change the presenter-selected content.
- Session reads and presenter changes are revisioned so the interface can detect stale state.
- The presenter can see whether the active participant browser has acknowledged the current revision.
- Browser acknowledgment does not prove comprehension, consent, authenticity, or admissibility.
Document and session flow
The original PDF remains in the presenter browser. The selected rendered page or uploaded image is transferred to the expiring participant session. Original filenames remain in the presenter browser, and the server enforces a neutral session display name. Sessions expire after 12 hours, and expired objects are queued for cleanup.
Possession-based participant access
The participant link is unlisted and expires, but it does not authenticate the participant's identity. Anyone who receives an unexpired link can view that session. Treat the link as sensitive, share it through an approved channel, and end the session when it is no longer needed.
Application safeguards
Implemented controls include response hardening, request-size and document-size limits, same-origin mutation checks, bounded event and transfer quotas, revision checks, expiring sessions, private object access through the application, operational health checks, and content-minimized billing records.
Current limitations
SiteLens does not provide customer-configurable MFA, SSO, tenant administration, organization or project authorization, immutable audit export, records retention controls, a production uptime SLA, 24/7 support, or compliance certification. The current release is not represented as suitable for confidential client plans and documents and should not be the sole document-delivery method in a meeting or review.
Evidence standard
Source code, hosted configuration, observed behavior, payment-provider state, operating records, and signed agreements are separate evidence sources. A feature implemented in code is not automatically enabled, independently tested, continuously operated, or contractually guaranteed.